Impact
The vulnerability resides in the application_status.php file of CodeAstro Online Job Portal 1.0. A crafted manipulation of the ID argument allows arbitrary SQL code to be injected, giving an attacker the ability to read, alter, or delete data from the database. This flaw cannot directly execute arbitrary code, but it can compromise the confidentiality, integrity, and availability of the underlying data.
Affected Systems
Only the CodeAstro Online Job Portal version 1.0 is affected; no other versions or components are listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, and the EPSS score is not available. The vulnerability is not yet listed in the CISA KEV catalog. Because the flaw can be triggered remotely through the web interface, and a published exploit exists, the likelihood of exploitation is considered realistic for attackers with web access.
OpenCVE Enrichment